1. The parties and their roles
Controller: the business running a loyalty programme in stmpr, whose guests the data comes from.
Processor: Leimeter Roland e.v., registered at Dabas, Hungary, contact [email protected]. VAT number 69246054-2-33. Registration number 52907795.
The processor handles guest data only on the controller's documented instructions. Using the service as intended counts as such an instruction: issuing the loyalty card, adding stamps, redeeming a reward, and sending messages the guest has consented to.
2. Subject matter, duration, nature and purpose
The subject matter is the digital loyalty card service: guests joining, stamps and rewards being recorded, Apple Wallet and Google Wallet cards being issued and updated, and notifications the guest has consented to.
The duration is the term of the service relationship between the controller and the processor. When it ends, section 9 applies.
The purpose is providing the service and nothing else. The processor does not use guest data for its own ends, does not analyse it alongside another customer's data, and does not sell it.
3. Data subjects and categories of data
Data subjects: guests who have joined the controller's loyalty programme.
Data processed: the identifying and contact details a guest provides, to the extent the controller asks for them on the join form; the state of the loyalty card, meaning the history of stamps, rewards and redemptions; the card's language; activity timestamps; and the fact, time and wording of any marketing consent, including a copy of the text the guest agreed to.
- The service is neither built for nor to be used for special categories of data under Article 9, health data among them.
- The controller is responsible for not asking on the join form for more than the loyalty programme needs.
4. Processor obligations
The processor handles guest data only on the controller's documented instructions, including any transfer to a third country, unless required otherwise by Union or Member State law. In that case it informs the controller before processing, unless the law forbids that notice.
The processor ensures that everyone authorised to handle personal data is bound by confidentiality.
5. Security measures
The processor applies the technical and organisational measures required by Article 32. They are described on the security page, which forms part of this agreement.
- Encrypted connections across the public site and the interfaces.
- Credentials for third party integrations are stored encrypted.
- Role based access, two factor authentication and passkeys on accounts.
- Staff access can be limited to a location and a role.
- Backups are encrypted and stored on a server separate from the application.
6. Sub-processors
The controller gives general authorisation for sub-processors. The processor binds every sub-processor to obligations equivalent to this agreement and remains liable for their work.
The current sub-processors are:
- Rackforest Kft. (Hungary): hosting, database and backup storage. Data is stored in Hungary, inside the European Union, backups included.
- Resend (email delivery): transactional messages to guests, such as reaching a reward.
- Apple Inc.: issuing and updating the Apple Wallet card and delivering its notifications.
- Google LLC: issuing and updating the Google Wallet card and delivering its notifications.
7. When a guest exercises their rights
Answering a data subject request is the controller's duty. The processor helps with the tools of the service: guest data can be viewed, corrected, exported and deleted from the dashboard.
If a request reaches the processor directly, it does not answer on the merits but passes it to the controller without delay.
8. Personal data breach
On becoming aware of a breach affecting data covered by this agreement, the processor informs the controller without delay, setting out the facts available.
Notifying the supervisory authority and the data subjects is the controller's duty. The processor makes the information it holds available for that.
9. Deletion and return when the engagement ends
When the service relationship ends, the processor returns or deletes the guest data at the controller's choice. Absent other instruction, a grace period follows the closing of the account, after which the data is permanently deleted.
Data that Union or Member State law requires to be kept, an accounting record among it, is excluded from that deletion.
Deleted data survives in the backups for as long as they are kept, about five weeks, and disappears from there too afterwards. A restore is only for recovering from an outage, never for bringing an individual record back.
10. Audits and information
The processor makes available the information needed to demonstrate compliance with this agreement, and allows for audits.
An audit is arranged in advance, held in working hours, conducted without unreasonable disruption to the business, and whatever it reveals is confidential.
11. Transfers outside the European Economic Area
Guest data is stored in Hungary, inside the European Union.
For Apple and Google, listed in section 6, processing may involve storage outside the European Economic Area. Those providers operate under the standard contractual clauses adopted by the European Commission or under an adequacy decision.
12. Term, changes and governing language
This agreement takes effect when the service is used and runs until the service relationship ends.
The processor may change this agreement where a change in the law or in the service calls for it, and informs the controller in advance of any material change.
The Hungarian version of this agreement governs. The other language versions are provided for understanding. Governing law: the law of Hungary. For questions or a signed copy: [email protected].